What the vulnerability does
01Description
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.
Explanation of Vulnerability in Simple Terms
02Summary
A low-impact information disclosure vulnerability in Active Directory/LDAP Integration allows authenticated administrators with high privileges to read limited sensitive data through network access. The vulnerability requires high attack complexity and does not affect data integrity or availability. Affected versions through 4.1.10 should be updated to a newer release.
What an attacker can do
03Attacker Capabilities
Read limited sensitive information if they have high-level admin access.
Potential impact on your site
04Site Impact
Minimal risk; only high-privilege admins can exploit this to view restricted data.
Conditions required to exploit
05Prerequisites
Attacker must be an authenticated administrator with high privileges and network access.
Key dates
06Disclosure timeline
September 26, 2023
CVE published
April 8, 2026
Record updated